Forum Discussion
Anthony_Vaz_547
Nimbostratus
Feb 10, 2010Is this a bad idea...
Hi guys
Curious on your thoughts on this please?
We traditionally have a setup where we may have web application servers and database servers in our corporate network.
...
hoolio
Cirrostratus
Feb 10, 2010Hi Anthony,
Without native character and path normalization functionality (or user-defined functions?) in iRules, I don't think it's a good idea to try to use iRules to perform HTTP security validation. It's quite simple to bypass most iRule URI validation with encoding/directory traversal attacks. See this post for details:
http://devcentral.f5.com/Default.aspx?tabid=53&forumid=5&tpage=1&view=topic&postid=3090031324
ASM can definitely provide good validation and protection. But I don't think iRules should be depended on for now for this scenario.
Aaron
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects